Pages:
Author

Topic: Fake Google Sheets Extension - Scammed | New Update! - page 2. (Read 391 times)

hero member
Activity: 1582
Merit: 758
From what you wrote, it seems that you use certain security solutions, the only question is, do you have proactive protection when it comes to Malwarebytes and do you use any other AV besides Windows defender? There is no doubt that this malware somehow found a way to get into your computer, the only question is how?

I always rely on premium security software with an always updated OS and I don't download any suspicious files, but sometimes it seems that even that is not enough to protect against infection. From your example, maybe we can learn that we should check the extensions we have in the browser as often as possible, and that maybe we should avoid Chrome and use some other browsers like Firefox, which is much better when it comes to privacy anyway.
To be brutally honest, I haven't bothered with my computer's security too much. I simply installed Malwarebytes and never fiddled with it again. The issue is that I can't recall how I possibly installed such an extension. I recently downloaded Adobe Lightroom from a pirated source, but that was a few days after the extension was created, thus, it's not associated.

On top of that, since it's not an actual virus, it's not detected by any antiviruses, nor VirusTotal. I don't know what other measures I could possibly take to make such a threat public.
legendary
Activity: 3234
Merit: 5637
Blackjack.fun-Free Raffle-Join&Win $50🎲
From what you wrote, it seems that you use certain security solutions, the only question is, do you have proactive protection when it comes to Malwarebytes and do you use any other AV besides Windows defender? There is no doubt that this malware somehow found a way to get into your computer, the only question is how?

I always rely on premium security software with an always updated OS and I don't download any suspicious files, but sometimes it seems that even that is not enough to protect against infection. From your example, maybe we can learn that we should check the extensions we have in the browser as often as possible, and that maybe we should avoid Chrome and use some other browsers like Firefox, which is much better when it comes to privacy anyway.
legendary
Activity: 3192
Merit: 1198
Bons.io Telegram Casino
Was this virus one of those clipboard viruses that changes the address you copy to the scammer's one? Or is this a new kind where you don't even see the real address on binance, only the scammer's ?

If it's the latter, holyshit how can someone actually protects himself from it? Since running an antivirus scan doesn't reveal anything.
Nope, it's not the well-known clipboard virus. It actually displayed the scammer's addresses instead of the actual ones. Binance's support agent was genuinely frustrated at first.

You have the whole community thanking you for not giving up and taking the time and effort to check your machine, if this was not caught by your anti-virus then everybody here is at risk if they are not checking the address, this is another scheme by hackers to steal coins, awareness is the key when transacting, you have to not only double check but triple check on addresses, we never know if we have this, even if we have these popular antiviruses.
hero member
Activity: 1582
Merit: 758
Was this virus one of those clipboard viruses that changes the address you copy to the scammer's one? Or is this a new kind where you don't even see the real address on binance, only the scammer's ?

If it's the latter, holyshit how can someone actually protects himself from it? Since running an antivirus scan doesn't reveal anything.
Nope, it's not the well-known clipboard virus. It actually displayed the scammer's addresses instead of the actual ones. Binance's support agent was genuinely frustrated at first. This is before deleting the extension.



And this is after deleting it, displaying the address support indicated as theirs.

hero member
Activity: 2856
Merit: 578
Leading Crypto Sports Betting & Casino Platform
After this post, I immediately checked all my extensions and checked if there are extensions that are on it that I don't remember putting in my browser, everybody should know this, and riskier because they cannot be traced by anti-virus, if you haven't done an extensive review of your extensions you will not know this, because all this time we trust everything that comes from Google, I wonder is it really coming from Google, I'm sure its not.
member
Activity: 82
Merit: 10
Was this virus one of those clipboard viruses that changes the address you copy to the scammer's one? Or is this a new kind where you don't even see the real address on binance, only the scammer's ?

If it's the latter, holyshit how can someone actually protects himself from it? Since running an antivirus scan doesn't reveal anything.
hero member
Activity: 1582
Merit: 758
Thank you for the warning OP. I would've never suspected the Google sheet extension to be the malware responsible for changing addresses.
btw, if an extension is grayed out doesn't that mean it's been disabled by the navigator?
This malware seems more dangerous even than the clipboard hijacker malware because it changes the actual address from source and therefore there is no way you would suspect it's been changed.

I would wipe out my computer's hard drive and reinstall the OS if I were you, though!
This time I was extremely lucky, because a few days ago I was actually planning on moving my funds from Binance in an attempt to find a better APY. Chances are, that I would have lost my money.

Damn! So my initial suspicion was correct. Yes, I think you were very lucky considering how small the amount was. For this reason, it is always a good idea to proceed each serious transaction with a smaller one to ensure that the funds will reach the intended destination.

Good detective work, by the way. It is too bad you could not figure out where you downloaded the extension to your browser. Who knows, there may even be different extensions infected with malware. Does anyone know why the extension name was greyed out?

My best guess is because it's not an actual functioning extension. A quick look at its main manifest.json file shows you what details it can present. If you click on any other extension, it opens up the extension or its settings (Metamask wallet opens wallet, Grammary opens up preferences etc.), the fake Google Sheets one didn't have an actual menu, thus, it doesn't have anything to open and appears grayed out.

legendary
Activity: 2520
Merit: 2853
Top Crypto Casino
Thank you for the warning OP. I would've never suspected the Google sheet extension to be the malware responsible for changing addresses.
btw, if an extension is grayed out doesn't that mean it's been disabled by the navigator?
This malware seems more dangerous even than the clipboard hijacker malware because it changes the actual address from source and therefore there is no way you would suspect it's been changed.

I would wipe out my computer's hard drive and reinstall the OS if I were you, though!
legendary
Activity: 1526
Merit: 1359
This time I was extremely lucky, because a few days ago I was actually planning on moving my funds from Binance in an attempt to find a better APY. Chances are, that I would have lost my money.

Damn! So my initial suspicion was correct. Yes, I think you were very lucky considering how small the amount was. For this reason, it is always a good idea to proceed each serious transaction with a smaller one to ensure that the funds will reach the intended destination.

Good detective work, by the way. It is too bad you could not figure out where you downloaded the extension to your browser. Who knows, there may even be different extensions infected with malware. Does anyone know why the extension name was greyed out?
hero member
Activity: 1582
Merit: 758
This thread is a follow-up of the previous thread I created, regarding a lost XRP deposit. For those who haven't read it and have limited time, I'll summarize.

(https://bitcointalksearch.org/topic/ripple-deposit-never-received-5408926)

I tried depositing XRP from Kraken to Binance, my deposit was never credited to my account and got me frustrated, thinking I've done something wrong. After several users suggested, I contacted Binance, and they told me that this wasn't their XRP address and recommended me to install Binance's app on my phone. To my surprise, the address I had on my phone was different from the one in my computer. Same thing occurred if I tried depositing other coins, such as BTC or ETH. I was baffled, the support agent mentioned that it's probably a malware on my computer.

I started with antivirus scans using Windows Defender and Malwarebytes, however, both showed no results. A few users suggested that it could be an extension on Chrome, decided to check, but nothing looked suspicious at first.

Google Sheets, Zen Mate, Ublock, Grammarly etc… Nothing suspicious, right? Except the fact that I don't recall installing the Google Sheets extension, but didn't think much of it, since I use Google services a lot (Drive, Docs, Excel), but noticed that for some strange reason, the name was grayed out, but the other extensions weren't.

I deleted the extension and Binance is now showing the proper address. Upon further investigation and opening its source file, it has a Javascript code that switches coin addresses with the scammer's address. On top of that, whenever I searched the scammer's XRP or BTC address, the tab would crash.





The issue is that I don't recall installing something like this on my own, unless it popped up and accepted its installation without realizing it. The extension's folder was created on 23/07/2022, it's relatively new and can't remember if I downloaded any pirate software or what else.

This time I was extremely lucky, because a few days ago I was actually planning on moving my funds from Binance in an attempt to find a better APY. Chances are, that I would have lost my money.
Pages:
Jump to: